Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 9, 2025

CVE-2025-4428

High
EPSS 43.4%CISA KEV
Ivanti/Endpoint Manager Mobile (EPMM)

Description

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.

EPSS — Exploit Probability

43.4%

Higher than 97.4% of all CVEs

Required Action

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM ; https://nvd.nist.gov/vuln/detail/CVE-2025-4428

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
43.4%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

May 19, 2025

Added to KEV

May 19, 2025

Remediation Due

Jun 9, 2025

Affected Product

Ivanti

Endpoint Manager Mobile (EPMM)

View all Ivanti CVEs